
CTSdatabase and GDPR
CertReports found no public GDPR evidence for CTSdatabase as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 18 Nov 2016
- Scope
- CTSdatabase is a duplicate subject detection database, which tracks the partial identifiers of individuals across sites and sponsors for the purpose of reducing the effect of duplicate or professional subjects on the outcome of clinical trials. We collect only partial identifiers of study subjects: initials, last four digits of their Social Security Number, date of birth, height and weight, and zip code of entering site. This information is used to protect the safety of study participants and the integrity of study data and to make sure appropriate study participants are included in clinical research. CTSdatabase processes special category data in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. CTSdatabase processes sensitive data in reliance on the Swiss-U.S. DPF. If there is a government or judicial audit, subpoena or warrant, data may be disclosed by CTSdatabase. If CTSdatabase merges with or is acquired by a Third Party, it is possible that PII may be disclosed, in which case study subjects will be notified of any changes in ownership or uses of their PII, as well as any choices they may have regarding your PII. However, since full identifiers are never entered into the system, there is no foreseeable way for fully identifying information to be disclosed.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | CTSdatabase, LLC: Inactive | Live pagesha256 19c237d00f |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is CTSdatabase GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.